Skip to content

feat(enrichment): Typosquat & dependency-confusion detector #1501

Description

@JSONbored

Context

A REES (review-enrichment service) analyzer. Tier: high-value.

Detects: A newly-added dep whose name is a near-miss of a popular package (edit-distance/homoglyph/scope-swap) OR an internal-looking unscoped name that is publicly claimable (namespace-takeover risk).

Data source: Bundled top-N popular-package list per ecosystem for the Damerau-Levenshtein/homoglyph compare; npm/PyPI registry 404 + scope-existence check for confusion; deps.dev for popularity rank. Free.

This is heavy/external/historical analysis the no-checkout headless claude --print reviewer cannot do; the REES returns it as a brief block the engine splices into the review (additive + fail-safe).

Implementation (established pattern, all inside review-enrichment/)

  1. Finding type + BriefFindings key in src/types.ts
  2. src/analyzers/<name>.ts — pure, inject fetch for tests
  3. Register in src/brief.ts ANALYZERS registry
  4. Render a public-safe block in src/render.ts
  5. node:test units against dist/ + a live smoke against the real data source

Deliverables

  • The analyzer + wiring + tests + a verifiable brief block (file:line or package@version)
  • Clean PR off main (zero engine conflict; outside the engine tsc/vitest/codecov scope)

Parent: #1499

Metadata

Metadata

Assignees

No one assigned

    Labels

    gittensor:featureGittensor-scored feature linked to a feature issue — scores a 0.25x multiplier.

    Projects

    Status
    Done

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions